CVE-2024-26251HighCVSS 6.8
Microsoft SharePoint Server Spoofing Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? The user would have to click on a specially crafted URL to be compromised by the attacker.
According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires multiple conditions to be met, such as specific application behavior, user actions, manipulation of parameters passed to a function, and impersonation of an integrity level token.
🎯 Affected products3
- Microsoft SharePoint Server 2016
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Server Subscription Edition
✅ Remediation
KB5002580 (Security Update) — fixed build 16.0.10409.20027 KB5002581 (Security Update) — fixed build 16.0.17328.20246 KB5002583 (Security Update) — fixed build 16.0.5443.1000
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26251
- patchhttps://www.microsoft.com/download/details.aspx?familyid=a78b1469-5945-4b65-baa5-073c90eb680d
- referencehttps://support.microsoft.com/help/5002580
- patchhttps://www.microsoft.com/download/details.aspx?familyid=af3ad2b9-74de-4f13-994c-5c2d701aff3c
- referencehttps://support.microsoft.com/help/5002581
- patchhttps://www.microsoft.com/download/details.aspx?familyid=1dfacdd2-10c9-4e5f-bf49-44dbd518ebf6
- referencehttps://support.microsoft.com/help/5002583